Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.9) | 0.23% | — | Invensys Wonderware IntouchSiemens Processsuite | 18/12/2012 | 16/6/2026 | Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file. | |
| Modificada | Media (6.9) | 0.45% | — | Invensys Foxboro Control SoftwareInvensys Infusion Ce/fe/scadaInvensys IntouchInvensys Intouch/wonderware Application Server+3 | 26/7/2012 | 16/6/2026 | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified… | |
| Modificada | Media (5) | 1.3% | — | Invensys IntouchInvensys Wonderware Application Server | 5/7/2012 | 16/6/2026 | slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause a denial of service (resource consumption) via a long Unicode string, a different vulnerability than CVE-2012-3007. | |
| Modificada | Media (5) | 2.2% | — | Invensys DasabcipInvensys Daserver Runtime ComponentsInvensys DassidirectInvensys Intouch/wonderware Application Server+1 | 5/7/2012 | 16/6/2026 | Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (5) | 16% | 💥 Exploit | Wonderware IntouchWonderware Suitelink | 6/5/2008 | 16/6/2026 | The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port… | |
| Modificada | Alta (8.8) | 3.0% | — | Wonderware Intouch | 20/11/2007 | 16/6/2026 | Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Intouch | 5/1/2006 | 16/6/2026 | SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter. |